codex-review
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute
git difffor collecting code changes and thecodexCLI for performing reviews. All CLI invocations are restricted with the--sandbox read-onlyflag to prevent unauthorized modifications to the workspace during the review process.\n- [DATA_EXFILTRATION]: Source code information gathered viagit diffis sent to the external Codex service for analysis. This behavior is the primary intended function of the skill. The use of the official Codex CLI and a read-only sandbox mode aligns with secure integration practices for AI-assisted development tools.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing untrusted code diffs and using the AI's output to influence commit decisions (Step 7: Commit Judgment). A malicious diff could potentially include instructions designed to manipulate the review scores.\n - Ingestion points: The output of
git diffis directly interpolated into prompts for the Codex engine.\n - Boundary markers: No explicit delimiters or instructions to ignore embedded code-level commands were identified in the prompt templates.\n
- Capability inventory: The agent uses Bash and decision logic to potentially approve or reject commits based on AI feedback.\n
- Sanitization: There is no evidence of specific filtering or sanitization of the code diffs before they are processed by the AI.\n- [SAFE]: The skill explicitly forbids the use of Codex MCP tools in favor of the more restricted CLI interface, demonstrating a commitment to secure operational constraints defined in the project's architecture decisions (ADR-004).
Audit Metadata